Skip to main content
Working document · Free, and free to forward

The Android
Release Gate

Ninety-eight tests, grouped the way OWASP groups them, with a column for your result and a column for where you read it. Then the two things no other checklist carries: the Google Play obligations and the RBI mobile controls that land on the same release as the testing.

98
Current tests, none deprecated
8
OWASP groups, privacy included
13
Sections, worked in any order

Why the number is 98

Because that is how many there are. OWASP's Android test set contains 96 current tests, plus two it tags as network but files in the Android tree and that exist for no other platform. There are also 14 placeholders — entries whose own page reads “This test hasn't been created yet and it's a placeholder”, carrying no steps and no evaluation criteria.

A checklist that counts those as tests cites fourteen things that do not exist. Every identifier in this document was resolved against the OWASP index on the review date printed on its cover, and none is deprecated and none is a placeholder.

That claim has an expiry, and the document says so on page one. OWASP deprecates tests at version boundaries, wholesale — so a checklist correct when written stops being correct at the next release, and the only remedy is to resolve every identifier again. Check the review date on the cover before you rely on it.

What is in it

9 Storage Read from allowBackup and the backup rules, external-storage call sites, what reaches logcat.
10 Cryptography Read from Cipher transformation strings, AndroidKeyStore parameters, key material in the binary.
5 Authentication and biometrics Read from BiometricPrompt configuration, and what a prompt actually gates.
15 Network communication Read from the Network Security Config, cleartext, custom trust managers, real traffic.
21 Platform interaction Read from android:exported, intent filters, custom permission protection levels, WebView.
15 Code quality and build settings Read from minifyEnabled, debuggable, the dependency tree, what is compiled in.
19 Resilience Read from the R8 configuration, integrity and root-detection call sites, and their failure behaviour.
4 Privacy Read from the merged manifest permission block, the SDK inventory, the Data safety declaration.

Then two sections that exist nowhere else. What else lands on the same release names the Play obligations testing does not touch — the target API level, package registration, the Data safety declaration, and the Financial Services permission list — and says plainly that a test evidences none of them. If the app belongs to a bank sets out the nine mobile controls RBI specifies for Commercial Banks, with our reading of where an Android build answers each one, and RBI's own note that five of the nine are illustrative.

The obligations are named and carry no dates. A deadline printed in a downloaded file is wrong the moment it moves, and nothing recalls a file from an inbox — so the dates live on this site, where they are corrected in one push.

The Android Release Gate

98 current OWASP Android tests, the Play obligations and the RBI mobile controls, in one working document.

By downloading, you agree to receive relevant communications. We respect your privacy.

Test identifiers and titles are from the OWASP Mobile Application Security Testing Guide. Copyright © The OWASP Foundation, licensed under CC BY-SA 4.0. For any reuse or distribution, you must make clear to others the license terms of this work. OWASP® is a registered trademark of the OWASP Foundation, Inc. Neither OWASP nor anybody else issues a certificate against these documents, and a completed copy of this checklist evidences nothing to Google or to a regulator — it is a record of what you checked and where you read it.

Want somebody else to work it?

Tell us the app, the form factors it ships on, and whether it is a bank's. Security Brigade has been CERT-In empanelled since 2008, with 693+ mobile application scopes assessed.

Describe the app